Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

271–280 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#271
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

> Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. This is a problem, because Microsoft operates in a lot of jurisdictions, but one of them always wants to be the exception and claims that it has jurisdiction over all the others. Not that I personally am of the opinion, that it is wise for the other jurisdiction to trust Micro…

You're arguing for corporate sovereignty.

I think you need to rethink your position.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#272
post #116

Earlier quoted context omitted.

At this point, end-to-end encryption is a solved problems when password managers exist. Not doing it means either Microsoft doesn't care enough, or is actually interested on keeping it this way

I wouldn't call the problem "solved" just because of password managers. Password managers shift the paradigm and the risk factors. In terms of MFA, a password in your manager is now "something you have " rather than "something you know ". The only password I know nowadays is my sign-in password that unlocks the password manager's vault. So the passwords to my bank, my health care, my video games are no longer "in my…

There's a lot of places or ways you can back up your vault for free. You don't need to deal with paper recovery codes if you don't want to.

(Separately, if you can get access to a computer I'm sure you can get access to a phone charger.)

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#273

Earlier quoted context omitted.

I don't think that many people here are naive enough to believe that any business would fight the government for the sake of its customers. I think most of us are simply appalled by this blatantly malicious behavior. I'm not buying all these "but what if the user is an illiterate, senile 90-year-old with ADHD, huh?" attempts to rationalize it away. it's the equivalent of the guy who installed your door keeping a copy…

Assume good intent. If Microsoft didn't escrow the keys, the next HN post would be "mIcR0SofT Ate mY chILDhooD pHOTos!!"

So don't secretly encrypt data someone else owns on their device!

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#274

Earlier quoted context omitted.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

Google Authenticator used to be disconnected from reality like this. Users were asking how to copy the codes to another phone, and they said "you can't, WAI, should add the other phone as a second auth method on every site." Like how people say you shouldn't copy SSH privkeys. I figured out an undocumented way to do it on iPhone by taking an encrypted iTunes backup though. Eventually they yielded on this, but their l…

On the security versus convenience spectrum, allowing a user backup and taking an automatic corporate backup are far apart.

Yes you should do the former. That doesn't say much about the latter.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#275

Earlier quoted context omitted.

For a long time, if you used full disk encryption, the encryption key never left your machine. If you forgot your password, the data was gone - tough luck, should have made a backup. That's still how it works on Linux. Pretty surprising they'd back up the disk encryption secrets to the cloud at all, IMHO, let alone that they'd back it up in plaintext.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

> That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious.

Do you feel equally strongly about people using drives that can fail? Is selling a computer without redundant drives also borderline malicious?

> In the real world, there is always a recovery path.

To accounts there is. But data gets lost all the time.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#276

Headline says “…if asked” Article and facts are “…if served with a valid legal order compelling it” ∴ Headline is clickbait.

I would prefer “it is impossible for Microsoft to give the keys because that’s not how their encryption works”.

You can change it it you like.

The way it is is important. Otherwise getting locked out is very easy. I think booting into safemode or messing with specific bios settings / certain bios updates enough to lock you out.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#277

Yes and this is a good thing. No organization, no matter how large or powerful, should be beyond the reach of the law.

I have no idea what you mean. If the user keys were protected, that would not put Microsoft beyond the reach of the law. To Microsoft it's just a few bytes they never do anything with.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#278
post #4

Veracrypt https://veracrypt.io/en/Home.html

And before that and before Trucrypt many used Jetico BestCrypt [1] not free... It can pretend the OS disk is invalid until a passphrase is typed. Only useful to fool smash-and-grab trash level thieves but I found it entertaining.

Either way once the Windows OS volume is unlocked it's all moot. There are many other ways to access ones machine remotely such as pushing a targeted update to the specific machine OS agnostic but easiest on Windows as Windows update fires off all the time despite patches being on a specific Tuesday. This method applies to phones as well, beyond the JTAG encryption bypass at power-up. Then a gag order is applied.

[1] - https://jetico.com/data-encryption/encrypt-hard-drives-bestc...

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#279
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

> Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. This is a problem, because Microsoft operates in a lot of jurisdictions, but one of them always wants to be the exception and claims that it has jurisdiction over all the others. Not that I personally am of the opinion, that it is wise for the other jurisdiction to trust Micro…

[deleted]

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#280

Earlier quoted context omitted.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

> That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. Do you feel equally strongly about people using drives that can fail? Is selling a computer without redundant drives also borderline malicious? > In the real world, there is always a recovery path. To accounts there is. But data gets lost a…

> Do you feel equally strongly about people using drives that can fail? Is selling a computer without redundant drives also borderline malicious?

No. Drives wear out and fail, like all hardware. Much like the compressor in your fridge, or V-belt in your car, you can extend the service life of your drive through proper care, and replace it when it fails to keep the system running. And in practice, hard drives are reliable enough that, with typical usage patterns, most people don't need RAID).

And, much like with fridges and cars, computers and their parts are subject to both market forces and (in more civilized places) consumer protection laws, which ensure computer hardware meets the usual, reasonable expectations of the common person.

> To accounts there is. But data gets lost all the time.

Data loss still happens, which kind of proves my point - computers are hard, and normal people can't even be expected to back things up properly. That's why every commercial PC and mobile OS vendor these days is pushing automated off-site backups using their cloud offerings. Might not be ideal, and even might be a tad anti-competitive, but it's a good deal for 99% of the users.

But this brings me back to my other pet peeve: 2FA, via authenticator apps, passkeys, and other such things that tie your credentials to a device via magic crypto keys. These crypto keys are data, and given how tech companies get away with having no actual customer support, 2FA ends up turning data loss into account access loss.

Mandatory 2FA is a trap, a time ticking bomb, because it's way too easy to make a mistake and lose the keys - and if the backend follows the current High Security Standards, this is irreversible even from the vendor side.

Compare that to expectations people have about the real world - if you lose all your keys to your home or your car, you... just go to a locksmith and show some plausible proof of ownership, and they'll legally break in and replace the locks for you. If you can't produce a plausible proof of ownership, you involve police in the process. And so on. There's always a recovery path.

Post reply on HN